VDB
GCVE-110-OSM-2026-10436
GCVE-110-OSM-2026-10436
Advisory PublishedCVSS 9.6/10
Suspicious package detected.
Microsoft removal context:
Extension ID: kruton.vscode-lambdamoo
Publisher: kruton
Removal Date: 8/9/2026
Violation Type: malware
Removed from the VS Code Marketplace by Microsoft for violating marketplace policies.
Source: https://github.com/microsoft/vsmarketplace/blob/main/RemovedPackages.md
GitHub exposure: 12 public file(s) on GitHub reference this extension (e.g. .vscode/extensions.json recommendations, devcontainer configs, or docs). These repositories may be distributing or recommending the removed extension:
- mthcht/awesome-lists: Lists/VSCODE Extensions/feeds/ioc_all_extension_ids.txt
- mthcht/awesome-lists: Lists/VSCODE Extensions/feeds/ioc_high_risk_extension_ids.txt
- microsoft/vsmarketplace: RemovedPackages.md
- kruton/vscode-lambdamoo: README.md
- nix-community/nix4vscode: data/openvsx/data_110.json
- vsxsentry/vsxsentry.github.io: feeds/ioc_all_extension_ids.txt
- vsxsentry/vsxsentry.github.io: feeds/ioc_high_risk_extension_ids.txt
- kruton/vscode-lambdamoo: package.json
- vsxsentry/vsxsentry.github.io: feeds/vsxsentry_opencti_import.csv
- vsxsentry/vsxsentry.github.io: feeds/vsxsentry_misp_warninglist.json
...and 2 more
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | kruton.vscode-lambdamoo | all (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.